Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - aesth

#1
21.7 Legacy Series / Re: Firewall and ASN
September 18, 2021, 08:29:26 PM
Quote from: pmhausen on August 17, 2021, 06:31:49 PM
Seriously how would you expect this feature to be implemented? A whois lookup for every packet is of course out of the question. Regular AS database updates? From which source?
whois -h whois.radb.net -- '-i origin AS714' | awk '/^route:/ {print $2}' > ip table alias
#2
Quote from: spikerguy on June 19, 2021, 01:29:25 AM
There is a working image gor freebsd and opnsense for NanoPi R2S as since the rtl drivers were recently merged in freebsd.


https://personalbsd.org/images/OPNsense-21.1-OpenSSL-aarch64-NanoPi-R2S-20210612.img.xz.

Please donate to sergey for all his effort at personalbsd.org
Feel free to join telegram chat for opnsense on arm @personalbsd
Thanks.

Nice! Thanks for the link.
#3
They only affect the displaying of the core performance boost. The core performance boost will work the same without them (but it will display 1000 even when it's at 1400).
#4
Okay, so it's not throttling. Thanks for checking.
#5
Could you check what frequency it's at while you're doing the test. It seems I was able to keep mine clocked at 1400 by placing additional heatsinks on the case.
(I don't really do speed tests myself however, my system performs fine at 1400 with good temperatures.)
Add:
hint.p4tcc.0.disabled=1
hint.acpi_throttle.0.disabled=1
hint.acpi_perf.0.disabled=1

To:
boot/loader.conf.local

And run:
sysctl dev.cpu.0

To see if the frequency drops.
dev.cpu.0.freq_levels: 1400/-1 1200/-1 1000/-1
dev.cpu.0.freq: 1400
#6
20.7 Legacy Series / Re: Suricata - Engine?
August 04, 2020, 08:06:19 PM
Quote from: spetrillo on August 04, 2020, 05:53:03 PM
Anyone seeing the "loading" on the Rules tab and it never goes away?

I was going to say: "yes now that you mentioned it". But it finished loading after I logged in, that took a while.
#7
Yep, same for me, also migrated (no checklists, no tests, sorry it just works). I am seeing slightly lower load average, much higher memory usage. Coreboot is v4.12.0.3.
#8
NTP is port 123
#9
I don't know about the FreeBSD image (I will wait for a working OPNsense image, not a developer), but armbian and friendlywrt both worked for me. R2S support will get merged into openwrt, so you won't need friendlywrt anymore.
#10
whois -h whois.radb.net -- '-i origin AS32934' | awk '/^route:/ {print $2}' | xargs pfctl -t facebook_networks -T replace

How would this command look if I wanted to output multiple ASN's to the same table?


Edit: Never mind, found a working solution.
#11
If a machine that is properly configured by default is the idea here, I'm all for it. It does seem to need some clarity somewhere in the GUI around why some rules are pre-selected to be enabled or disabled, some are drop actions, some alert. It takes a lot of time to know every rule so most users have to resort to trust in developers anyway. Macros that enable/disable pre-selected advisable rules would be useful and this does fit into the simplicity philosophy.
#12
This is hardware chaining heaven. Looking forward to messing with this.
#13
That's odd I had no trouble installing on an APU2. Maybe try with updated firmware or a different drive? https://pcengines.github.io/#mr-32
#14
The new one looks very interesting considering the price. Does it have an issue with heatsink installation as it says in the review on the site? I would rather not order it if I have to solder.

Thanks.
#15
Yes, and no IPv6 support.